Skip to content
  • There are no suggestions because the search field is empty.

Does whitelisting compromise our cybersecurity in any way?

No, you can whitelist Nimblr’s simulations without compromising your cybersecurity defenses using Microsoft advanced delivery policy for third-party phishing simulations.

Is whitelisting Nimblr simulations safe for our email security?

Yes. Whitelisting uses Microsoft's Advanced Delivery policy, a mechanism designed specifically for phishing simulations that does not weaken your overall email security posture.

How does the whitelisting work?

Whitelisting is configured in Microsoft 365 via the Advanced Delivery policy under Defender for Office 365. An administrator adds Nimblr's authorized sender domains and IP addresses to the policy, which then routes only Nimblr simulation emails past phishing filters while leaving all other filtering fully active.

Does this policy bypass malware or unwanted email filtering?

No. This configuration does not bypass standard malware or unwanted email filtering. It only ensures that Nimblr’s authorized simulation emails are not flagged as false positives by Defender for Office 365. The policy applies to specific sender domains and IP addresses verified by Nimblr and limited to simulation traffic only. Microsoft designed this mechanism precisely to allow controlled simulations while fully preserving the integrity of your security environment — no other senders benefit from the policy, and it does not apply to real phishing emails.

Are employee credentials at risk during simulations?

No. Our simulated phishing login pages automatically interrupt password entry after the first two characters. No data is transmitted, stored, or processed in any form.